LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 02-03-2006, 12:36 PM   #1
nomb
Member
 
Registered: Jan 2006
Distribution: Debian Testing
Posts: 675

Rep: Reputation: 58
Wanting advice on setting up a honeypot/proxy


I am going to use an old dell I have as a proxy server so I can share the internet through my Desktop. I am thinking of going like this.

[HTML]
Cable Wireless Wired Wireless
|-----| |-----| |----| |----|
Internet-Router_One-My_Desktop_Comp-Router_Two-Laptop[/HTML]

First I guess I need to ask if there are any recomended distros that I should use on my Desktop. Secondly are there any recomended proxys? I keep seeing one called Squid I was going to try that. Thirdly, Is it a security risk having your proxy server run a honeypot program. And of course fourthly , are there any recomended honey pot programs? I love networking and linux so I finally decided to combine the two . Should the proxy run the firewall? Anything better than IP tables? Sorry that I have a lot of questions.

Any help I can get would be awsome. Oh, I was thinking of using SSH to login to my proxy cause I only have one monitor and I don't have a KVM switch yet ><. Any thoughts on that?

Last edited by nomb; 02-03-2006 at 12:38 PM.
 
Old 02-03-2006, 02:07 PM   #2
bulliver
Senior Member
 
Registered: Nov 2002
Location: Edmonton AB, Canada
Distribution: Gentoo x86_64; Gentoo PPC; FreeBSD; OS X 10.9.4
Posts: 3,760
Blog Entries: 4

Rep: Reputation: 78
Squid is the de facto unix proxy, just as apache is the de facto unix webserver. You may well want to use it just because its popularity ensures the greater amount of tutorials/help/documentation available for it.

Quote:
s it a security risk having your proxy server run a honeypot program.
Well, since the entire point of a honeypot is to entice people to hack it, I would say this is a very bad idea. In fact it is a terrible idea. If you truly want to set up a honey pot then use a dedicated machine in a DMZ well separated from the LAN segment of your network.

Quote:
Should the proxy run the firewall? Anything better than IP tables?
Well, sounds like you need to set up a busybox/firewall on whichever machine is the gateway of your network. And what's wrong with iptables? Iptables is an extremely powerful and configurable tool for creating firewalls. And besides, I am not sure there is anything else available. Perhaps someone has ported BSD's pf to linux? I will tell you all those other firewall programs available are simply scripts/GUI frontends for iptables. Still, I recommend writing your iptable scripts from scratch to gain a better understanding of how it works.

I also think you should hold off on the honeypot until you have more experience with networking/security as willfully opening holes into your network is not something to be undertaking without a great deal of understanding od what you're doing.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
*working* kernel based keylogger for honeypot? TotalDefiance Linux - Security 4 11-05-2005 11:25 AM
Advertising honeypot? Dark_Helmet LQ Suggestions & Feedback 17 09-16-2005 05:40 PM
Need advice for internet sharing proxy that supports filtering peterbrowne Linux - Networking 1 11-12-2004 05:27 PM
explain honeypot and tarpit? servnov Linux - Networking 3 09-30-2004 07:53 PM
Setting up a Server Need some Advice monkeywork Linux - Software 1 11-20-2003 10:08 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 10:08 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration